SUSPICIOUS — rixejesad.pdf
SUSPICIOUS — rixejesad.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (58/100). 3 of 53 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
a19679e6eb75a65d620cde20dc10074132b0e31a0efced3173e02b39834787d7 - SHA-1:
3b8c49b31118c2eb47d51a0a032e17b25cc03567 - MD5:
f7bbc9df0b7ebca94c1e1acd21bd92cd - ssdeep:
768:ugGzpDqz9WgKglUH0rDiT1aUyXaX2rUiKsT+xste9wEhJwIs/9vhN:LGFWYFeD61Mr4+e9bwIs/9vhN - TLSH:
T1AA32AEF3546BED8D7E9A9B132DA211661585DA887137E6B018C8763CC8BC7FC6F00921 - Submitted as: rixejesad.pdf
- File type: pdf · Size: 43562 bytes
- Verdict: suspicious (58/100)
Detections (3 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Trojan.Script.Generic
MITRE ATT&CK
Why this verdict
The suspicious score of 58/100 is the fusion of 4 weighted signals:
- Embedded link rated suspicious by URL analysis: http://deviraf.mystylepursesshop.com/uploads/1/3/0/9/130969018/puvipatalel-mukatanolek.pdf - network signal, weight 0.40, confidence 0.60
- Embedded network infrastructure: https://ggtraff.ru/strik?keyword=electrolysis+process+pdf, https://cdn.shopify.com/s/files/1/0428/9835/8432/files/7868051279.pdf, https://cdn.shopify.com/s/files/1/0428/4976/3487/files/27643395185.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://ggtraff.ru/strik?keyword=electrolysis+process+pdf
- https://cdn.shopify.com/s/files/1/0428/9835/8432/files/7868051279.pdf
- https://cdn.shopify.com/s/files/1/0428/4976/3487/files/27643395185.pdf
- https://cdn.shopify.com/s/files/1/0429/5540/7519/files/guided_reading_levels_by_grade_chart.pdf
- http://files.taylorlavati.com/uploads/1/3/1/4/131437074/tusotox_lojudotoraladim_nowuporolonaxez.pdf
- http://latuselid.naturehillsfarm.com/uploads/1/3/2/8/132814930/tofakixafapujodaxe.pdf
- http://files.reviverestorativeretreats.com/uploads/1/3/1/1/131164246/41dd72c8.pdf
- http://files.omeganulodi.org/uploads/1/3/1/4/131455621/gaxod.pdf
- http://deviraf.mystylepursesshop.com/uploads/1/3/0/9/130969018/puvipatalel-mukatanolek.pdf
- https://cdn.shopify.com/s/files/1/0433/0687/7080/files/25618010541.pdf
- https://cdn.shopify.com/s/files/1/0432/7990/9028/files/5814439636.pdf
- http://jarabek.peakperformanceprep.com/uploads/1/3/0/8/130874359/70fd92.pdf
- http://vilexo.artbcause.com/uploads/1/3/1/4/131438477/virowarogasisunin.pdf
- http://files.sacred-seed.co.uk/uploads/1/3/0/8/130873965/mipetolukam.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- ggtraff.ru
- cdn.shopify.com
- files.taylorlavati.com
- latuselid.naturehillsfarm.com
- files.reviverestorativeretreats.com
- files.omeganulodi.org
- deviraf.mystylepursesshop.com
- jarabek.peakperformanceprep.com
- vilexo.artbcause.com
- files.sacred-seed.co.uk
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report